Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4cv6-9jjm-xp2g

Опубликовано: 27 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6

Описание

phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowing authenticated attackers to delete arbitrary files by exploiting insufficient sanitization in Image::delete(). Attackers can delete the database.php configuration file to disable the installation gate and access the public setup wizard to create new superadmin accounts.

phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowing authenticated attackers to delete arbitrary files by exploiting insufficient sanitization in Image::delete(). Attackers can delete the database.php configuration file to disable the installation gate and access the public setup wizard to create new superadmin accounts.

EPSS

Процентиль: 25%
0.00325
Низкий

8.6 High

CVSS4

Дефекты

CWE-22

Связанные уязвимости

nvd
11 дней назад

phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowing authenticated attackers to delete arbitrary files by exploiting insufficient sanitization in Image::delete(). Attackers can delete the database.php configuration file to disable the installation gate and access the public setup wizard to create new superadmin accounts.

EPSS

Процентиль: 25%
0.00325
Низкий

8.6 High

CVSS4

Дефекты

CWE-22